People who say things like this rarely also want the hassle that comes with it. Key exchanges, re-keying: all a big PITA. But iMessage (and WhatsApp) do key exchanges facilitated by a trusted broker. If you didn't trust the broker, you would have to do more work when making an initial exchange with a peer and more work if they lost their phone/keys.
iMessage has always been a compromise with subtle rough edges. But we trusted Apple because they talked about privacy and made it clear that their business model meant that we should trust them more than competitors. But now, precisely because of how good and effective they secured their devices -- they fear regulation and thought that they could further compromise things and people would go along with it.
We are over a year into a pandemic which involved wide-scale lockdowns. Physical key exchange is a nonstarter for broad adoption.
I think the emphasis is on the -ed in involved. That's a temporary condition which is already resolving in much of the world. You may also be overestimating lockdown compliance among average people.
If iMessage had been designed to require a brokerless key exchange, its security would be superior (though in this case, Apple's interception software trumps everything). But iMessage would appear to be less convenient than alternatives like WhatsApp (brokered key exchange, re-keying).
We would be in a much better position right now with email privacy if the version of PGP that doesn't defend from an active attack would have been deployed worldwide.
That’s a wee bit different from showing YouTube previews imo.
> And nice that you abuse your karma to downvote people who don't agree with you.
I did not downvote you; not that you be able to tell if I did, anyway.
"More than 90 policy and rights groups ask company to abandon plans for scanning phones of adults for images of child sex abuse.". Maybe YOU weren't talking about csam, but everyone else was including the article author, if you even read it.
I pointed out that's not true (that's probably why other people downvoted your comment) and that you're apparently confusing the iMessage stuff with the CSAM scanning stuff which, as I already said, are completely separate from each other.
https://developer.apple.com/library/archive/technotes/tn2444...
I want the real thing.
If you used iOS/iMessage, you have always trusted Apple. To be truly 'end to end' you would assume that there's no opportunity for another party to intercept your messages: the only trust would be in the keys you exchanged with your peer.
1. They are a trusted broker for iMessage key exchanges. You didn't do the key exchange, you assumed that when Apple did so on your behalf that you're really communicating with the peer you think you are.
2. They designed the iOS features that you trust keep iMessage data inaccessible to other untrusted software on your device.
3. They designed the secure enclave and make public statements that they won't compromise it for law enforcement. You trust that their deeds in private match their public statements.
I'm not in agreement with this being ok, but if it truly is on device, it still technically can be E2EE
What do you think this software does when it finds a matching hash entry? Toss a notification to ask you nicely to pop round your nearest FBI office?
What meaning does 'end-to-end' have anymore if this applies? If Apple wrote software on-device to forward a copy of all messages prior to encryption to iCloud for 'backup', would it still be end-to-end? What if they sent it to an AdTech firm to index for interesting terms that match products you should be pitched? The software in this case is still Apple's, running on-device.
I'd suggest you read up a bit on this - https://www.apple.com/child-safety/
What we're discussing is this feature:
"The Messages app will add new tools to warn children and their parents when receiving or sending sexually explicit photos.
When receiving this type of content, the photo will be blurred and the child will be warned, presented with helpful resources, and reassured it is okay if they do not want to view this photo. As an additional precaution, the child can also be told that, to make sure they are safe, their parents will get a message if they do view it. Similar protections are available if a child attempts to send sexually explicit photos. The child will be warned before the photo is sent, and the parents can receive a message if the child chooses to send it.
Messages uses on-device machine learning to analyze image attachments and determine if a photo is sexually explicit. The feature is designed so that Apple does not get access to the messages."
There are no visual derivatives, no neural hashes, and nothing is sent to apple.